Law / Micronesia

Micronesia

5 of 7 named instruments researched to a stage, across three of the six areas of law we track: 3 in force and 2 proposed. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law 1
  4. Cybersecurity law 3
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Scraping law1 instrument, 1 in force

Research summary (227 words)

The Federated States of Micronesia has no scraping-specific statute, so general law governs each dimension separately.

The national Crimes title (Title 11) has no computer-misuse or unauthorized-access offense; FSM Congress Bill C.B. No. 24-14 (Cybersecurity Act 2025), which would add a new Chapter 4 to Title 21, would regulate only the cybersecurity practices of an owner of designated critical information infrastructure, not create a general offense reaching a person who reads or crawls an ordinary public web page.

No FSM court has addressed the enforceability of a browsewrap or clickwrap terms-of-service against a scraper, or established an unfair-competition, misappropriation, or trespass doctrine for scraping, and no source assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

The FSM Copyright Act (Title 35, Chapter 1) permits fair use for purposes including criticism, comment, and research, but contains no text-and-data-mining-specific exception or opt-out, so relying on fair use to train a model on scraped copyrighted text rests on the same general, multi-factor test as any other use.

The Act protects an original compilation as a literary work reaching only the compiler's own selection and arrangement, and confers no separate sui generis database right of the kind some other jurisdictions recognise. The Federated States of Micronesia has no comprehensive or sectoral privacy law reaching personal data scraped from a public FSM website (see this jurisdiction's privacy-topic finding).

Copyright and text and data mining (TDM)

FSM Copyright Act, exclusive rights, fair use, and compilation protection

FSM Code Title 35, Ch. 1 (Copyrights), secs. 101-109Official text of the FSM Code

In force. Binds public and private bodies.

What this law does

Section 106 of the FSM Copyright Act gives a copyright owner the exclusive right to reproduce, prepare derivative works from, distribute, perform, and display a copyrighted work, subject to section 107's fair-use exception, which reaches reproduction for purposes such as criticism, comment, news reporting, teaching, scholarship, or research, weighed against the purpose and commercial character of the use, the nature of the work, the amount used, and the effect on the work's market.

No text-and-data-mining-specific exception or opt-out mechanism exists in the chapter. Section 101 defines a compilation as an original work of authorship formed by selecting, coordinating, or arranging preexisting material or data, and section 103 confines a compilation's copyright to the compiler's own contribution, not the underlying material, so the Act confers no separate sui generis database right over data a scraper collects.

Willful infringement for commercial advantage or private gain is a criminal offense (section 123), and any infringement of the exclusive rights arms the copyright owner with a civil action for an injunction, damages, and court-imposed punitive damages (section 122); the chapter's own text does not state the calendar date on which it took effect.

What it requires

Cybersecurity law3 instruments, 1 in force, 2 proposed

Research summary (864 words)

The Federated States of Micronesia's one enacted operator-facing security-posture duty for a private-sector duty-bearer sits inside its general telecommunications regulatory law, and a second, broader critical-infrastructure cybersecurity framework is pending before its national legislature but had not yet passed as of September 2026.

The FSM Code's own online index, hosted by the Asian Development Bank-funded Legal Information System at fsmlaw.org, is an unofficial codification frozen at Public Law No. 12-12 of August 2001, and its 58 titles carry no Computer Crimes, Cybersecurity, or Electronic Transactions title or chapter as codified there; Title 11 (Crimes) stops at Chapter 12 (Sentencing) with no computer-offense chapter, and Title 21 (Telecommunications) as codified there holds only the original 2001-era Chapter 1 (General Provisions) and Chapter 2 (Telecommunications Corporation).

Because that codification is stale, the national legislature's own current public-law and bill archive at the Congress of the Federated States of Micronesia's website (cfsm.gov.fm) was searched instead.

Two companion bills were introduced in the Twenty-Third Congress on May 17, 2025: C.B. No. 24-15 would add a new Chapter 13 to Title 11 defining cybercrime offenses such as unauthorized access, computer-related fraud, and cyberstalking, an intruder-offense bill this jurisdiction's scraping row already names; and C.B. No. 24-14 (the Cybersecurity Act 2025), researched here, would add a new Chapter 4 to Title 21 establishing a critical-information-infrastructure cybersecurity framework, a National Cybersecurity Committee, and a national Computer Emergency Response Team (CERT-FSM).

Neither bill carried a Congressional Act number as of September 2026, meaning neither had passed the Congress.

No further search of the 18th through 23rd Congresses' enacted public-law titles surfaced any other cybersecurity, data-protection, or electronic-transactions statute; the only enacted operator-facing security duty found is Public Law No. 18-52 (2014), the 'FSM Telecommunications Act of 2014,' inserted as a new Chapter 3 of Title 21, and section 349(1)(b) of that chapter is this jurisdiction's coded telecommunications-safeguards instrument below.

No comprehensive data-protection or breach-notification statute exists for this jurisdiction's privacy row to carry a security-of-processing clause from, so there is no Test 2 seam to defer to here.

C.B. No. 24-14's Subchapter III (sections 407 through 412) creates the operator-facing duties coded as two proposed instruments below, one for the risk-management measures a critical-information-infrastructure owner must implement and one for the incident-reporting clock the same owner must meet.

Title 21's older Chapter 2 (Telecommunications Corporation) and the enacted Chapter 3 survive alongside the bill's proposed Chapter 4, so the Federated States of Micronesia Telecommunications Corporation, the Chapter 2 incumbent operator, continues to hold its own separate statutory powers; whether it is itself a Chapter 3 licensee bound by section 349(1)(b) is not established in the text located here and is recorded as an open question on that instrument.

C.B. No. 24-14's Subchapter V would separately require a person providing an accreditable cybersecurity service, such as a security operations center or penetration-testing service, to hold an accreditation from an officer the Secretary of Justice appoints; that duty binds a narrow class of security vendor this corpus's activity vocabulary cannot yet express, so it is named here in prose rather than filed as a coded instrument, the same treatment already given Vanuatu's near-identical cybersecurity service-permit regime.

Section 27 of the bill would delay Subchapter V's own commencement until the Secretary of Justice promulgates implementing regulations, later than the rest of the chapter's ordinary commencement on presidential approval.

Section 382 of the enacted Telecommunications Act of 2014 separately criminalizes unauthorized access to a communications facility, interception, and data damage or disruption, an intruder-offense chapter already within the scraping topic's computer-misuse family and not itself a security-topic duty on an operator or manufacturer.

No Central Bank or IT-risk directive for a licensed financial institution was located: the FSM Code's Title 29 (Commercial Banking), Chapter 6 (Regulation and Supervision of Banks, sections 601-627), uses the word 'security' only for loan collateral and carries no confidentiality, safeguards, or cyber provision, and no public website for a Federated States of Micronesia Banking Board or equivalent financial regulator could be located to check for a lower-visibility prudential directive (a guessed domain returned no DNS record), so that remains an open research gap rather than a confirmed absence.

Whether the World Bank, the Pacific Islands Forum, SPC, or the ITU assisted in drafting C.B. No. 24-14 was not established in the sources checked; that absence rests on the primary sources browsed directly, since a broader web search could not be run, so it is an open gap rather than a settled absence.

Several sources returned no usable text: fsmtc.fm (the Telecommunications Corporation's own site) and fsmgov.org each served only a JavaScript shell on both the compliant and browser tiers; the FSM Congress's legacy fsmcongress.fm domain failed with a certificate hostname mismatch at the TLS layer on every scheme tried, a genuine site-side misconfiguration rather than a bot wall, which is why the current cfsm.gov.fm domain was used instead; PacLII's Federated States of Micronesia index returned a Cloudflare CAPTCHA challenge, a stop rather than a wall to read past; and no working WIPO Lex jurisdiction profile page for the Federated States of Micronesia could be located by direct URL, so the cross-check used for other jurisdictions in this corpus is unavailable here.

Sector security regimes

FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties

§§ 407-411, Subchapter III, C.B. No. 24-14 (Cybersecurity Act 2025), proposed new Chapter 4, Title 21, FSM CodeC.B. No. 24-14

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

C.B. No. 24-14 (Cybersecurity Act 2025), introduced in the Congress of the Federated States of Micronesia, would add a new Chapter 4 to Title 21 whose purpose is to establish a legal framework to prioritize cybersecurity as a means to advance the national policy to strengthen and maintain secure, functioning, and resilient critical information infrastructure in the Federated States of Micronesia.

Section 407 would let the Secretary of Justice designate a computer, computer system, or computer data as critical information infrastructure by written order to its owner. Section 407(1)(a) requires that the computer or computer system be necessary for the continuous delivery of an essential service, and section 407(1)(b) separately requires that its loss or compromise could significantly degrade, impede, disrupt, or otherwise adversely impact delivery of that service.

Section 408(1) would make the owner of critical information infrastructure responsible for implementing technical, operational, and organizational measures to manage cybersecurity risks and to prevent or mitigate the impact of a cybersecurity incident or threat.

Section 408(2)(a) requires a cybersecurity risk assessment of critical information infrastructure at least every two years, alongside an internal cybersecurity policy, an internal incident-reporting policy, and an internal cybersecurity awareness program.

Section 409(1) would let the Secretary require the owner to provide information on the design, configuration, and security of critical infrastructure, and section 410 would let the Secretary issue binding written directions to an owner or a class of owners to manage a cybersecurity threat or risk. Section 411 requires the relevant owner to notify the Department of Justice of a change of ownership or control within seven days.

A failure to comply with the owner's duties under section 408 is a criminal offense carrying a fine of up to $10,000 or imprisonment of up to one year or both, and section 419 would let the Secretary exempt any person or class of persons from all or part of these obligations. This duty does not yet bind: C.B. No. 24-14 was introduced in the Congress of the Federated States of Micronesia on May 17, 2025, and had not passed as of September 2026.

What it requires

FSM Telecommunications Act of 2014, Security Safeguards for Customer Information

§ 349(1)(b), Title 21 (Telecommunications), Chapter 3, FSM Code, as inserted by Public Law No. 18-52 (2014)Public Law No. 18-52 (2014), Congress of the Federated States of Micronesia, as published by the Congress's own website (cfsm.gov.fm)

In force since 3 April 2014. Binds public and private bodies.

What this law does

Section 349(1) of Title 21, inserted by Public Law No. 18-52 (2014), the 'FSM Telecommunications Act of 2014', binds a telecommunications licensee with two duties under the same subsection. Paragraph (a) bars collecting, using, maintaining, or disclosing information about a customer without the customer's consent, a duty this jurisdiction's privacy row researches.

Paragraph (b), researched here, separately requires the licensee to apply appropriate security safeguards to prevent the collection, use, maintenance or disclosure of that information without the customer's consent.

Section 383's general offence provision makes a contravention of any provision of the Act, including section 349(1)(b), a criminal offence, and section 384 sets escalating fines and imprisonment for a natural person and a percentage-of-revenue fine for a corporation or other entity, with an added daily fine for a continuing violation.

Section 387 lets the Attorney General appoint Special Assistant Attorneys General to prosecute offences under the Act, and no civil action or private right of action for a customer harmed by a safeguards failure was found; a customer's recourse instead runs through the Telecommunication Regulation Authority's own consumer complaint and dispute process. Public Law No. 18-52 gave this new chapter of Title 21 the short title 'FSM Telecommunications Act of 2014'.

Section 94 of Public Law No. 18-52 sets its own effective date as the date of presidential approval, dated April 3, 2014.

What it requires

Vulnerability and incident reporting

FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock

§ 412, Subchapter III, C.B. No. 24-14 (Cybersecurity Act 2025), proposed new Chapter 4, Title 21, FSM CodeC.B. No. 24-14

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 412(1) of the same bill, C.B. No. 24-14 (Cybersecurity Act 2025), would require the owner of critical information infrastructure to notify the Secretary of Justice and the CERT-FSM (the national Computer Emergency Response Team the bill would create) of a significant cybersecurity incident affecting its critical information infrastructure or an interconnected system. The owner must submit an early warning within twenty-four hours of becoming aware of the incident.

The owner must then submit a fuller incident notification within seventy-two hours. The owner must submit a final report not later than thirty days after that notification, and, for an ongoing incident, a progress report on the same thirty-day clock. Section 412(3) would separately require the owner to establish mechanisms and processes for promptly detecting a cybersecurity threat or incident affecting its critical information infrastructure.

A failure to comply with the reporting duty is a criminal offense carrying a fine of up to $10,000 or imprisonment of up to one year or both. This duty does not yet bind: C.B. No. 24-14 was introduced in the Congress of the Federated States of Micronesia on May 17, 2025, and had not passed as of September 2026.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (106 words)

The Federated States of Micronesia has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no hot-news or misappropriation doctrine, no reported case on hyperlinking or framing, and no text-and-data-mining-specific exception or opt-out mechanism.

The general fair-use exception of the FSM Copyright Act (Title 35, Chapter 1 of the Code) reaches an aggregator's reproduction of a headline or short extract to the extent the use is for criticism, comment, news reporting, or a similarly weighed purpose, and a compilation of headlines or extracts is itself protectable as an original work of authorship only for the aggregator's own selection and arrangement, not for the underlying material aggregated.

Snippet reproduction

FSM Copyright Act, fair use exception reaching news reporting

FSM Code Title 35, Ch. 1, sec. 107 (Limitation on exclusive rights - Fair use)Official text of the FSM Code

In force. Binds public and private bodies.

What this law does

Section 107 of the FSM Copyright Act exempts the fair use of a copyrighted work, including reproduction, for purposes such as criticism, comment, news reporting, teaching, scholarship, or research, from copyright infringement, weighed against the purpose and commercial character of the use, the nature of the work, the amount used relative to the whole, and the effect on the work's potential market.

Section 101 defines a compilation as an original work of authorship where preexisting material or data is selected, coordinated, or arranged, and section 103 confines a compilation's protection to the compiler's own contribution rather than the underlying material assembled into it.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.